PHPJabbers Night Club Booking Software
cpe:2.3:a:phpjabbers:night_club_booking_software:*:*:*:*:*:*:*
- 1.0
A denial-of-service vulnerability has been identified in PHPJabbers Night Club Booking Software version 1.0, stemming from a lack of rate limiting in the 'Forgot Password' feature. This oversight allows attackers to flood a legitimate user's email with excessive password reset requests, potentially overwhelming the user's inbox.
Exploitation of this vulnerability could lead to a denial-of-service condition for the affected user, caused by an influx of email messages.
To reproduce this vulnerability, log into the PHPJabbers Night Club Booking Software demo site. Use an email address that is already registered. Capture the request for the 'Forgot Password' feature using a tool like Burp Suite, and send it to the Intruder tab. Configure the Intruder to send multiple requests and start the attack. The result will be a large number of password reset emails sent to the registered email address.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.